here knows jenkins? If anyone knows, please tell me if this permission matrix secure enough for a public github repo. I have configured a webhook on github for pull requests and I wanna run this pipeline on a new PR on the new branch.
Why should an random visitor be able to trigger builds?
Seems like he is also contributing or has forked the repo and contributed
with random visitor i mean absolutly anyone. Even bad actors can trigger an build. without that permssion they can still read the builds and builds should be triggered by people who are trusted enough, by webhooks or by new git commits (fetching the repo)
I thought triggering builds with GitHub pull requests require that permission. Thankyou for the information
Обсуждают сегодня